AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73842

CRITICAL · CVSS 9 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

OpenChoreo versions prior to 1.0.3, 1.1.3, and 1.2.0-rc.2 expose sensitive API endpoints without proper authentication, allowing unauthorized access to Kubernetes Secrets, the ability to mutate workloads, and execute commands across data planes. This critical vulnerability poses a significant risk to any organization using affected versions of OpenChoreo for Kubernetes, and immediate upgrades to the patched versions are essential to mitigate potential exploitation. Kubernetes administrators and security teams should prioritize this update to protect their environments from unauthorized access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73842
Severity
CRITICAL
CVSS
9
EPSS
0.18%
Kubernetes

Original NVD Description

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.